recommended request timeout value in application gateway backend setting for WAF v1 and v2

Karipe, Shivani 1 Reputation point
2022-05-18T10:15:54.907+00:00

We are using Application Gateways with WAF v1 and v2 configurations. We have kept the request timeout value in the backend setting to 30 min.
is this recommended? and what is the recommended timeout value
203143-backend-setting.png

we also want to know, if we keep the request timeout to 30min, is there any security risk associated with it?

@SaiKishor-MSFT / @suvasara-MSFT /anyone who can help on this

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
964 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Luis Rodriguez 6,191 Reputation points Microsoft Employee
    2022-05-18T11:06:14.45+00:00

    Hello @karipeshibani

    Welcome to Microsoft Q&A Platform,

    If your application can take more than 30 seconds to respond then you have to increase this value. If not there's no need to change it.

    I don't see security risks in configuring to 30 minutes, as long your application needs it.

    https://learn.microsoft.com/en-us/azure/application-gateway/configuration-http-settings#request-timeout

    https://blogs.perficient.com/2016/12/23/azure-application-gateway-10-lessons-learned/

    I hope this helps!

    ----------

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments